Very interesting! I had not heard of these incidences.
HN user
lamlam
To add to this, while the Superfish issue only affected their consumer laptop lines (e.g. IdeaPad), the LSE issue was found on their enterprise lineup (e.g. ThinkPad).
So yes, in a normal case, one would expect to be safe because they are using their own built image. But Lenovo went much further than simply installing crapware, they added a firmware that updates files on startup in the OS to ensure that they had a way to install whatever they wanted onto your system [1].
[1] https://www.theregister.co.uk/2015/08/12/lenovo_firmware_nas...
I'm always surprised that Lenovo use in the enterprise space didn't take a hit after all this came to light. I would have thought competitors like Dell and HPE would have used that opportunity to disparage Lenovo.
Here's an interesting discussion involving many of the players directly involved in the project. Ann Cavoukian from the Engadget article is on this.
Actually, what's really interesting is to compare her outlook from earlier this year https://youtu.be/oEyBjYNgaMY
No one takes a company public for fun. They do it for funds. Especially for something like a car company that requires a lot of initial investment to get going. They can't start making money right away like a SaaS company might.
I've always been very curious, that given that the American health insurance lobby is as powerful as it is, why it hasn't successfully lobbied for more accessible abortions. It seems that they stand to gain a lot if women who didn't want children didn't have them as the added stresses of having an unwanted child probably reduce long term health.
How about screen time, do they watch them on tablets/devices or on a media player on a TV?
Sorry if my comment implied I had kids, I do not. But in terms of access I see a lot of other comments further below talking about downloading everything locally and serving it through plex, which seems like a solid idea.
If kids are known for one thing, it's their ability to watch and re-watch the same piece of content over and over. We have decades of good, high quality, children's media. Why do they need the latest and untested greatest?
Well I did say 1-2h in the GP.
I would not consider that acceptable. I guess the assumption is that you would commute into Toronto for work. But that is not what I was talking about. I meant that there were places close by that one could have a life. For example, Kitchener-Waterloo, London, Hamilton. All these places have way more affordable housing and job opportunities.
I feel this is a bit sensationalized. If one didn't want to put up with Toronto housing prices, there are many other affordable choices within 1-2h drive from Toronto. No need to pack up and move to Winnipeg which, btw, is the murder capital of the country [1]. And this is in a year that Toronto is seeing some of its worst gun violence since the mid 2000s.
[1] https://globalnews.ca/news/4347007/manitoba-has-highest-homi...
I like fastmail personally because aside from being a fast experience, I like their well written guides and articles. It helps me set stuff up without feeling like I'm just following instructions and helps me understand what I'm doing and why I'm doing it.
Could you please expand on this? My understanding was that hydrogen was produced through electrolosys. What process does one use to go from a hydrocarbon to H2? And does that process produce CO2?
Bitcoin? Visa gift cards? Temporary Visa cards from places like entropay?
Do ARM chips have ME or PSP equivalents? It would be great to be able to buy a new machine and use something like coreboot without having to use hacks to disable ME.
I'm a bit confused as to why adguard is being targeted here, but things like Disconnect.me which also use a "fake" VPN are not. Can anyone shine some light on this?
While many would not be able to afford a trip to Canada, I would think there would still be a sizeable number who live within 1-2h from the border who could drive there for non-emergency care.
I've often wondered if we could open up private clinics in Canada for Americans where we charge reasonable rates. Kind of start a medical tourism industry by the border.
The security issue, which the security firm refers to as the Firebase vulnerability
IMO, calling the vulnerability the "Firebase vulnerability" makes it seem like it's a problem on Firebase's side. But is it really their problem? At what point do we start blaming the developers instead of the service?
I believe whatsapp is free now? I actually only remember paying once.
Huh. This is great! Might be a NameCheap (my registrar) limitation. The way it's worded in the management page on NameCheap is that DNSSEC is not supported for .ca period. Definitely something I'll look into. Thanks!
I like what CIRA (the .ca registration authority) does. The default is for them to hide your contact information. You have to opt-in to make it public.
They then handle all communications people want to send to you. More registration authorities should take stances like this.
Now if only they could get DNSSEC support...
Also not an expert, but since videos are transcoded as key-frames and changes applied to those key frames, I don't think it's as simple as segmenting something like a CSV. Transcoding is probably required just for the segmentation process. Putting it back together might be easier, but the final output file might also be larger because of overhead.
Just to add onto this, there's a whole field of people who design things with human psychology in mind. For example, when you got onto Twitter, they _could_ show you how many notifications you have right away, but they implemented an artificial delay so you stare at it intently and when it finally shows you feel gratification [1].
So while a design may not make sense right away, there may be other factors at play.
[1] https://www.vice.com/en_ca/article/vv5jkb/the-secret-ways-so...
Yes, making things _arbitrarily_ difficult would probably go against the spirit of the law, even if it technically complied with it. But as Alex3917 pointed out, as long as a company responded to GDPR requests by email in a timeline in accordance with the law, they would be safe.
One important thing to not about some of these points is that they don't have to be made easy for users. For example, in relation to "Abilty it export data", there doesn't necessarily need to be a feature on the website for it to be compliant. They simply need to do it if you ask. So if that means having someone manually run a query to get a data dump every time someone asks, it's still considered compliant.
Of course that doesn't actually scale. That's why most all the big players are providing export features.
If you clicked the link and found the amount of information they have on your surprising, and now feel a bit violated, then good; you should.
You'll probably try to do a bit of research and try to figure out how to opt out of all this and protect yourself. And you should. But you shouldn't just stop there.
Many of the people who are reading this right now are responsible for designing and implementing systems that collect massive amounts of data. I implore you to not just think about your own privacy moving forward, but the privacy of your users. Security and privacy should be two of your top level concerns when designing systems, not just tack-ons.
Simply hating of Google/Facebook/$$$Corp for invading your privacy and not doing anything to rememdy the general poor state of privacy in the modern connected world when you have the power to do so is hypocritical.
Next time you're given a project that has PII and the security user story gets deprioritized, raise it as an issue. Aside from being the right thing to do, many places, such as Canada and California, are looking at GDPR-like regulations. So it makes sense to do it now instead of later.
And if you're going to argue that it's hard, and it's time consuming, and you're a startup just trying to get on their feet so you can't be bothered, then consider that you may be part of the reason we find ourselves in this sorry state.
/rant
Yes, but they can be hit or miss, and I simply don't have the time or funds to be testing multiple models.